Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs

0
Medium
Vulnerability
Published: Wed Jun 17 2026 (06/17/2026, 06:53:58 UTC)
Source: SecurityWeek

Description

SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. The post 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs appeared first on SecurityWeek .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/17/2026, 07:00:27 UTC

Technical Analysis

Defused and KEVIntel have observed active exploitation attempts against three Fortinet FortiSandbox vulnerabilities: CVE-2026-39808 (OS command injection), CVE-2026-39813 (authentication bypass), and CVE-2026-25089 (remote command execution). CVE-2026-39808 and CVE-2026-39813 were patched in April 2026, while CVE-2026-25089 was patched in June 2026. Exploits for these vulnerabilities have been detected in the wild, with some created using AI techniques. Separately, SOCRadar detected a campaign compromising over 30,000 Fortinet firewalls and VPN gateways by scanning for devices and using a curated list of known passwords to gain access. The attackers collect credentials from compromised devices to facilitate further intrusions. The compromised systems span more than 190 countries, including India and the United States, and include sensitive sectors such as defense. The threat actor's infrastructure was partially exposed, allowing researchers to analyze their operations. Fortinet has released patches addressing these vulnerabilities.

Potential Impact

Successful exploitation of CVE-2026-39808 and CVE-2026-25089 allows remote unauthenticated attackers to execute arbitrary commands on vulnerable FortiSandbox appliances, potentially leading to full system compromise. CVE-2026-39813 enables attackers to bypass authentication controls, facilitating unauthorized access. The large-scale compromise of Fortinet firewalls and VPN gateways (FortiBleed campaign) exposes corporate and government networks to unauthorized access, credential theft, and persistent monitoring. The collection of credentials from compromised devices enables attackers to expand their access footprint, increasing the risk of data breaches and espionage, especially given the involvement of defense industry VPN endpoints.

Mitigation Recommendations

Fortinet has issued official patches for CVE-2026-39808 and CVE-2026-39813 in April 2026 and for CVE-2026-25089 in June 2026. Organizations using FortiSandbox appliances should apply these patches immediately to mitigate the vulnerabilities. For Fortinet firewalls and VPN gateways, it is critical to change default or known weak passwords, implement strong password policies, and monitor for unauthorized access. Since the threat actor uses credential stuffing techniques, organizations should consider multi-factor authentication where possible and review access logs for suspicious activity. Patch status is confirmed as official fixes are available. No vendor advisory indicates that no action is required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/","fetched":true,"fetchedAt":"2026-06-17T07:00:15.431Z","wordCount":1114}

Threat ID: 6a3245ff0b89be6888ebe892

Added to database: 6/17/2026, 7:00:15 AM

Last enriched: 6/17/2026, 7:00:27 AM

Last updated: 6/17/2026, 4:25:25 PM

Views: 44

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses